T09 · Insecure Skill Coding Practices
- Location
SKILL.md:34- Finding
Excessive Interaction Telemetry Without Defined Privacy or Security Controls
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 34–41
Vulnerability Type: Privacy-invasive telemetry and insecure sensitive-data logging
Risk Level: MediumVulnerable Snippet
text ├── meta:operation_id / timestamp / operator / page_context / config_type ├── geo:region / country / city / timezone / locale / currency ├── interaction:user_input / input_type(natural_language|quick_action|template) / │ agent_parse / agent_questions / form_filled / user_modified / │ final_submitted ├── execution:api_calls / cross_system / validation_results / submit_status ├── compliance:rules_checked[] / rules_passed[] / rules_blocked[] / override_reason ├── localization:languages[] / currency / tax_rules_applied ├── calendar:nearby_events[] / cultural_flags[]Technical Analysis
The Skill requires every interaction to be logged and defines a broad telemetry schema containing operator identity, raw user input, Agent-generated content, form values, final submissions, precise geographic context, API activity, cross-system activity, compliance decisions, and calendar-related information.
The surrounding workflow also requires periodic analysis, delivery of reports to Feishu, and eventual movement of older raw records into cold storage. However, it does not define:
- Redaction of credentials, authentication tokens, personal data, or confidential business information.
- Purpose-based field minimization or restrictions on recording raw prompts and API payloads.
- User notice or consent requirements.
- Encryption in transit or at rest.
- Role-based access controls or tenant isolation.
- Sanitization before reports are delivered to an external collaboration platform.
- A verified deletion process or user-controlled retention policy.
- Restrictions against using sensitive raw records for AI analysis.
Consequently, an implementation that follows these instructions litera ...[truncated 1915 chars]
- Remediation
View remediation
Remediation Suggestions
-
Apply data minimization
- Do not record raw prompts, complete API payloads, credentials, tokens, or final submissions by default.
- Replace operator identities with scoped pseudonymous identifiers where attribution is not essential.
- Reduce precise city-level location to the minimum geographic granularity required.
-
Add mandatory secret and personal-data filtering
- Detect and redact passwords, access tokens, API keys, session cookies, payment data, and regulated personal information before persistence.
- Perform filtering before data is sent to AI analysis or external reporting systems.
- Reject or quarantine records when safe redaction cannot be guaranteed.
-
Define access controls
- Enforce least-privilege, role-based access for logs, reports, and cold storage.
- Isolate records by tenant, region, and environment.
- Record and monitor every read, export, modification, and deletion operation.
-
Protect stored and transmitted data
- Require authenticated encryption at rest and TLS for all data transfers.
- Store encryption keys in a managed key service with rotation and separation of duties.
- Prohibit plaintext exports and unrestricted report links.
-
Secure external reporting
- Send only aggregated and anonymized statistics to Feishu.
- Exclude raw prompts, operator identities, precise locations, API details, and low-volume categories that could permit re-identification.
- Require an approved destination, restricted membership, expiration controls, and data-loss-prevention scanning.
-
Implement retention and deletion controls
- Establish field-specific retention periods based on necessity rather than moving all records to indefinite cold storage.
- Support verified deletion from active storage, backups, reports, indexes, and AI-processing datasets.
- Require explicit approval before extending rete ...[truncated 322 chars]
-
